Skip to main content

Rule A · Article 32 GDPR

Courts do not require infallibility, they require demonstrable diligence

The modest measure you can prove is worth more than the investment you cannot evidence.

A court does not convict you for having suffered a breach. It convicts you when, asked what you had in place the day before, you cannot answer with documents. That is the whole difference. And it is a difference that is prepared beforehand, never afterwards.

Article 32 does not ask you for a perfect system

Article 32 of the GDPR requires appropriate technical and organisational measures. It does not say infallible. It does not say the best on the market. It says appropriate, and the adjective is chosen deliberately: it calls for a case-by-case judgement, having regard to the nature of the data, the context of the processing and the real risk you are taking on.

For the person who signs, the problem changes shape. The operating question is no longer ‘am I protected?’, which is a question with no possible answer and no end. The question is another one: ‘if tomorrow I have to explain my conduct to a judge, what do I explain it with?’. The first is answered with budget. The second, with paper.

Diligence is assessed in the particular case

The Madrid Provincial Court of Appeal (Audiencia Provincial de Madrid) made this plain in a personal data breach case. It did not measure the defendant's degree of sophistication. It measured its conduct: what it did, when it did it and what record remained.

SAP Madrid 371/2023, of 28 July
[...] acted diligently in complying with the obligations imposed on it in the event of a personal data breach. [translation]

It acquitted. Not because the incident had not happened, but because the defendant's conduct in the face of the incident withstood examination. Read it slowly: the court did not assess a result, it assessed a behaviour. And a behaviour is either evidenced or it is not.

The modest measure you can actually prove

The same decision found adequate a measure that no supplier would sell you as sufficient.

SAP Madrid 371/2023, of 28 July
[...] the data was handed over [...] by means of an Excel file protected by a password known only to the Chair and the Secretary of the Committee [translation]

A password-protected file and two identified people with access. That is all. What turned that modest measure into a defence was not its strength, but three features a judge can check: it existed before the incident, it restricted access to specific people and it could be described unambiguously at trial.

The modest measure you can evidence is worth more, in the courtroom, than the investment you cannot document.

Why investment with no trace does not defend you

Almost every company that comes to us after a breach had spent money on protecting itself. The problem was not the absence of measures: it was the absence of dates. Nobody could say when each thing was put in place, who decided it or what had been reviewed the previous year.

That gap has an immediate procedural consequence. What is not on the record is not pleaded; and what is reconstructed after the event with stray emails and employees' memories reaches trial with the solidity of a draft. The other side need only point at the holes. In what a court really looks at when the claim arrives you will see the five points where those holes always appear.

What turns a measure into evidence

  • A certain date: when it was put in place and from when it was operating.
  • A written decision: who approved it and on what grounds, even if it is three lines in a minute.
  • Named scope: who has access, to what and under what authorisation.
  • Periodic review: a record that it was checked and that it was still in force.
  • A trace of the incident: what was detected, at what time, who decided and what was communicated.

Not one of those five points is a systems matter. They are five matters of company governance, and that is why you decide them.

The mistake of waiting for the incident

A breach compresses time. When it arrives, the notification clock is running, those affected are asking questions and the other side's lawyers are already drafting. It is the worst imaginable moment to start manufacturing the file on your diligence, because everything you produce from that instant is born under suspicion of having been made for the case.

The file is built in cold blood, with the company running and no urgency. It costs little and nobody notices it. It is noticed only on the day it is needed, and on that day it is worth everything.

Three questions before you sign the next quotation

  1. Will this measure be documented with a date, or only installed?
  2. Will I be able to describe on one page who has access to what thanks to it?
  3. If a judge asks me tomorrow for proof that I had it, do I hand it over within a week without reconstructing anything?

If the third answer is not a calm yes, the spending improves your protection but it does not improve your position before a court. They are two different things and it is worth not confusing them when you approve the budget line.

Does this mean I can protect myself lightly if I document it well?

No. The measure must still be appropriate to the real risk of your processing. What the decision teaches is that appropriate does not mean expensive. Documenting an insufficient measure does not make it sufficient; but failing to document an adequate measure does make it useless as a defence.

Does an internal email count as proof of the date?

It is worth more than nothing and less than an orderly record. An isolated email proves a moment; a maintained inventory proves sustained conduct, which is what is assessed.

And if the breach was caused by a supplier?

Then the first battle is not about your measures, but about who held the capacity of controller or processor in that system. And that is decided by the data processing agreement, not by the reality of who had access.

You can check in a few minutes where you stand: the Breach Management Test measures your ability to prove what you already do, not the security of your systems.

Could you evidence your diligence today?

Twelve questions, one per screen. At the end you will get your Defensibility Index and know what evidence you are missing at each point.

Take the Breach Management Test
articulos/art32-seguridad-diligencia
Article 32 GDPR: demonstrable diligence, not infallibility | ILP Abogados